Every so often an attack campaign arrives that is remarkable not for its sophistication but for its absence of it. The Snowflake campaign, which began surfacing in May 2024, is the definitive modern example. There was no zero-day, no malware on the victim's network, no clever lateral movement. There was a username, a password, and an account without multi-factor authentication.

The credentials came from infostealer malware — the quiet, unglamorous plague that sits on infected personal and contractor machines harvesting every saved login in the browser. Some of the credentials used were years old. They still worked, because the accounts they opened had never been given a second factor, and because nobody had thought of a data-warehouse tenancy as a crown-jewel system. Snowflake itself was not breached; the attackers walked into customer environments, one company at a time, and copied out whatever those companies had stored there. By the campaign's end roughly 165 organisations were implicated, and the resulting disclosures — Ticketmaster and Santander in the first wave, AT&T in July — made it the year's largest theft of consumer data.

The uncomfortable part is how ordinary every failure was. Cloud platforms had been sold on the promise that security was included; the fine print always said shared. Customers configured the tenancy, chose the authentication, and owned the outcome. May 2024 is when the industry discovered how many had read the brochure rather than the contract — and it is the reason enforcement of MFA, rather than the mere availability of it, became the default across major platforms within the year.

Also that month · Hospitals on paper

Ascension goes back to handwriting

On May 8, ransomware struck Ascension, one of America's largest non-profit health systems, spanning roughly 140 hospitals. Electronic health records went offline, ambulances were diverted, medication administration reverted to paper, and clinical staff spent weeks working without the systems their workflows are built around. Investigators traced the entry point to an employee inadvertently downloading a malicious file. Health systems remain the most consequential ransomware target: the disruption is not an inconvenience but a clinical risk, and the recovery is measured in weeks of degraded care.

Also that month · Scraped, not hacked

Dell's 49 million records

Dell disclosed that a threat actor had obtained records relating to roughly 49 million customer orders — names, physical addresses, and hardware details — not by breaking in, but by abusing a partner portal's API, reportedly registering as a partner and querying it at scale until the dataset was assembled. No malware, no exploit. It was a lesson in a category defenders systematically under-weight: an interface that answers too many questions too quickly is a breach waiting for someone patient enough to ask.

India desk · May 2024

CERT-In flags an intrusion at BSNL

On May 20, 2024, India's Computer Emergency Response Team reported a possible intrusion and data breach at BSNL — a fact later confirmed by the government in a reply to Parliament. BSNL is not merely a telecom operator; it is the state-owned carrier serving rural districts, government offices, and strategic installations where private networks do not reach. Details were sparse at the time and remained so, which was itself part of the story: the incident surfaced through official channels rather than corporate disclosure, and Indian users learned about it largely through parliamentary answers. It was an early argument for what the DPDP framework would eventually require — that breach notification be an obligation to the affected, not a disclosure made at the breached party's convenience.

⏳ Time capsule — May 2024

  • OpenAI's GPT-4o demo and Google's Gemini announcements dominated the technology conversation; security teams began asking who owned the prompts.
  • Ticketmaster's breach arrived mid-tour-season, giving the story an unusually engaged public.
  • "Shared responsibility model" moved from cloud-certification jargon into board-deck vocabulary.
  • India's general election ran through the month, with cyber teams on heightened alert throughout.
Where it stands today — 2026

The login as the new perimeter

Snowflake changed platform defaults across the industry: enforced MFA, mandatory network policies, and credential-hygiene checks that treat an old saved password as the live liability it is. It also marked the point where identity, not the network, became the thing defenders actually guard — the through-line that runs from here to the Salesloft token theft of 2025 and the OAuth campaigns of 2026 documented elsewhere in this archive. The infostealer economy that supplied the credentials only grew, culminating in the sixteen-billion-record compilation that panicked the internet in June 2025. And Ascension joined the permanent case file for why healthcare ransomware is a patient-safety issue before it is an IT one.